Report: Outdated browsers put 637m users at risk

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

A group of researchers on Tuesday said 637 million web users are surfing with outdated internet browsers and are, therefore, at greater risk of web-based attacks.

Using data collected from Google web searches and security firm Secunia, the researchers — Stefan Frei of ETH, Zurich; Thomas Dübendorfer of Google; Gunter Ollmann of IBM ISS; and Martin May of ETH, Zurich — analysed the browsers used in a report. The researchers aimed to understand why so many recent attacks by criminal hackers have been aimed at the browser, and why those attacks have been so successful.

Overall, the authors found that roughly 40 percent of users were utilising insecure versions of web browsers. Among the least upgrade-compliant were users of Internet Explorer (IE), which currently dominates the internet-browser market.

The data was collected in mid-June 2008. Of the users, 78 percent employed IE, 16 percent Firefox, three percent Safari, and 0.8 percent Opera. The percentage of these users who were running the latest version of their browser was 52 percent for IE, 92 percent for Firefox, 70 percent for Safari, and 90 percent for Opera.

The authors noted that it has taken IE7, the current Internet Explorer release, 19 months to gain only 52 percent of the entire Internet Explorer audience. Forty-eight percent of the users in the study were either using an old version of IE7 or still had IE6 installed.

Some of this has to do with how the respective suppliers provide updates. IE7 is currently offered as an auto-update with each monthly set of Microsoft security patches, yet a number of people are opting out of the upgrade and still running IE6.

The study did not include use of insecure browser add-ons, such as older versions of Adobe Reader, because the data from Google contained only the browser information.

The study made comparisons to the food industry, arguing that people understand the need to buy the safest foods, but not to use the safest version of browsers. The study asked whether internet browsers, like food, should display expiration dates. The authors provided an example of a browser that displayed in red in the upper-right-hand corner: "145 days expired, three updates missed."

However, unlike in the food industry, there is no liability for software vendors. And, the authors noted, software vendors are not legally obliged to provide software updates.

Talkback

Some of the blame for the large proportion of surfers using outdated versions of IE has to be laid at Microsoft's door. IE7 is not available to those of us still running Windows 2000.

79196 2 July, 2008 10:22
Reply

one reason for this could be that hacked copies of xp which do not get passed M/S security can not update to IE7 it may reflect just how many hacked copies are out there

tanker12uk 2 July, 2008 11:36
Reply

I would like to see how many of the people that haven't upgraded have either dial-up connections or slow unstable broadband. I think you would find that they go hand in hand. I know my folks never update their system, because all they have is dial-up. I mean if you had dial-up would you upgrade?

spartus4 4 July, 2008 04:30
Reply

I have tried to do that for a number of my customers in the end it was cheaper to do it by either taking the unit back to my base or belive it or not via mobile connection as most of the isp's here wont hold the connection long enough to get the upgrade

tanker12uk 4 July, 2008 10:50
Reply

I use Firefox, which I prefer to IE7. I was a beta tester and hit many issues with IE7 which has rather put me off installing it. Occasionally I have to use the IE6 rendering engine with Firefox (using IE Tab) either because the page won't display correctly in Firefox, or because it uses ActiveX controls. Presumably this would flag me as an IE6 user. If so, a reluctant one!

38895 4 July, 2008 11:08
Reply

Considering IE7 was built on the IE6 engine I don't really see any advantage to upgrading, security is not that much better. They have just copied some of Firefox's features to try to keep pace.

ator1940 7 July, 2008 14:04
Reply

Its always easy to blame the vendor but in this instance, I don't see why it's Microsoft's fault that some users won't update their browsers. the updates are there, users know where to find them and in some cases are notified of them, what more can they do? force users to upgrade?
They don't make any money on browsers, so don't expect a huge marketing push.
In my opinion by making the updates available and notifying you, they've done enough.

harpless 7 July, 2008 18:51
Reply

Perhaps that's why Bill's leaving...before it all comes grinding to a halt!

'Hey, ya can't blame me, I don't run the place anymore.'

TFD

thinkfeeldo 8 July, 2008 05:12
Reply

I have access to stats for over 50 sites covering a range of genres and never seen the less than 25% Firefox users in the last 6months. Infact in most cases it's around 34%. Agree with the figures for percentage of IE7 to IE6 users though. On tech sites there is usually more IE7 users than IE6 and on non-tech sites it is usually IE6 that has it's nose in front but in each case it's pretty even between the two.

I don't think it's microsofts responsibilty to force users to upgrade. They have IE7 as the default browser on their latest OS and prevented the install of IE6 and have included IE7 as a free update or manual download.

The only way I see IE6 users finally being forced to update is either:
1) wide spread attacks on the less secure browser - scaring users into updating.
2) Web developers stop supporting it (most sites require some tweaking to get it to render in IE6 correctly when this stops people will eventually have enough of looking at broken pages and will upgrade)
3) Microsoft stop selling XP and users are eventually forced onto vista or a newer OS which will not support IE6

I personally hate IE6 users as I have to spend so much time tweaking just for them and cannot use some cool new features/tricks that other browsers support because IE doesn't. IE6 users are holding back the web.

David Long 9 July, 2008 10:33
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

22 minutes ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

41 minutes ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

17 hours ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

17 hours ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

19 hours ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

19 hours ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

20 hours ago by apexwm on Windows 8 start-up speed forces USB boot workaround
Gavin Goodman

You can now buy the Xi3 modular computer in the UK at http://www.ocdistribution.com . This can be bought with the Tand3m software, pricing and...

21 hours ago by Gavin Goodman on CES 2012: Xi3 microSERV3R
Phil at Cloud4

I agree: Mike Lynch can clearly build a business and manage strategy. I suspect the exit of Mike is more likely the end of a planned handover...

24 hours ago by Phil at Cloud4 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Phil at Cloud4

This is unbeleivable government wastage with only one winner... Microsoft 1 - Tax payer Nil!

1 day ago by Phil at Cloud4 on 6 million wasted licences and £1,200 PCs: welcome to government IT
Mispam

So what do you do when you can't boot into windows? Why can't I just hold Shift while I power up instead of having to boot into windows and click a...

1 day ago by Mispam on Windows 8 start-up speed forces USB boot workaround
apexwm

I've also seen that Mac OS X for Intel machines is supposed to run in VirtualBox, which would also be a nice solution. I've never tried it though.

1 day ago by apexwm on xTreme Triple Booting: Linux, Mac & Windows
dave heasman

What I wonder is why when companies are caught bang to rights in not providing contracted services, people bend over to smear the customers? Surely...

1 day ago by dave heasman on Virgin throttles broadband for high-speed customers
pjc158

Strange statement from HP regarding Mike Lynch and not capable of scaling a company. Autonomy was a $7bn purchase which started as a small company...

1 day ago by pjc158 on HP cuts 27,000 staff as Autonomy chief Lynch leaves
lojolondon

Or - possibly, they will destroy business by ensuring people do not invest where there is no return. Another socialist idea, well beyond it's...

1 day ago by lojolondon on Open Data Institute will act as biz incubator
J.A. Watson

Good stuff Jake, very interesting. Thanks. jw

1 day ago by J.A. Watson on xTreme Triple Booting: Linux, Mac & Windows
openhgs

"the cost of a second LCD screen is about the same as one day of an office worker's time, so this should soon be recouped in extra productivity."...

1 day ago by openhgs on Windows 8 could speed multi-monitor uptake
Thomas Gellhaus

I also installed the KDE version; I also will probably try out razorqt since I really haven't had a chance to before. I'm looking forward to the...

2 days ago by Thomas Gellhaus via Facebook on Mageia 2 Released
francisabigail

Acquiring when reinvention/cannibalization is too challenging for a large organization can be an excellent strategy- still, so many mergers stumble...

2 days ago by francisabigail on Ariba buy parks SAP on Oracle's cloud turf
apexwm

All of the feedback regarding using a touch monitor for a desktop PC is right on. Several months ago, we installed a "demo" multitouch all-in-one...

2 days ago by apexwm on Windows 8 could speed multi-monitor uptake